vendor:
EDraw Flowchart ActiveX Control
by:
shinnai
7.5
CVSS
HIGH
Insecure Method
284
CWE
Product Name: EDraw Flowchart ActiveX Control
Affected Version From: EDraw Flowchart ActiveX Control (EDImage.ocx) v. 2.0.2005.1104
Affected Version To: EDraw Flowchart ActiveX Control (EDImage.ocx) v. 2.0.2005.1104
Patch Exists: NO
Related CWE:
CPE: a:anydraw:edraw_flowchart_activex_control:2.0.2005.1104
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
EDraw Flowchart ActiveX Control (EDImage.ocx v. 2.0.2005.1104) “HttpDownloadFile()” Insecure Method
The vulnerability allows an attacker to download and execute arbitrary files on a targeted system using the 'HttpDownloadFile()' method in EDraw Flowchart ActiveX Control (EDImage.ocx v. 2.0.2005.1104). By convincing a user to open a specially crafted web page, an attacker can execute arbitrary code on the system with the privileges of the user.
Mitigation:
To mitigate this vulnerability, users should avoid opening untrusted web pages or clicking on unknown links.